Backdoor

How to remove “Backdoor:Win32/PcClient.CM”?

Malware Removal

The Backdoor:Win32/PcClient.CM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/PcClient.CM virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Backdoor:Win32/PcClient.CM?


File Info:

name: 4427D9420C9E4FD908A7.mlw
path: /opt/CAPEv2/storage/binaries/4009a466ad227dd88e100b1a6f99a69aa28155092b7f11b875dc9b237b7a9633
crc32: CBD8EB1F
md5: 4427d9420c9e4fd908a79b4315ca7d55
sha1: 2ea985242a45f3ba89ddda476e39a35863581d03
sha256: 4009a466ad227dd88e100b1a6f99a69aa28155092b7f11b875dc9b237b7a9633
sha512: 59672ebdef147432e9550ee80ac6262412e6f78c1a6945b57343eff37e5c3783f65552fcae695c361cc61ac806fd1dcfe69d21d00b2406b9fd68b998dac44b55
ssdeep: 1536:KyplSbm1rtAO5NBMnKFCvJgZP1aU2bYupYP5V51X5Xn4S:Kypsbm1rtnPwZEPgK4YP5VHJXnZ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1B1A36B1A958547FAD513E871A19EEF36C6B20E5012914283A3C7FF7E38B3151F70AA1B
sha3_384: 8af500702217be4d2d7571e8554c4ab0b655feaf86619aaa3dec46320494c343d7e9dcbfee2ad7520f16807fc12d6d29
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2010-08-12 06:18:52

Version Info:

0: [No Data]

Backdoor:Win32/PcClient.CM also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.PcClient.kYKa
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.824344
FireEyeGeneric.mg.4427d9420c9e4fd9
CAT-QuickHealBackdoor.Pcclient.19199
SkyhighGenericRXAS-DS!4427D9420C9E
McAfeeGenericRXAS-DS!4427D9420C9E
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/PcClient.f4d71024
K7GWBackdoor ( 0020e5af1 )
K7AntiVirusBackdoor ( 0020e5af1 )
BaiduWin32.Backdoor.PcClient.w
VirITBackdoor.Win32.Generic.ADVS
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PcClient.NGZ
APEXMalicious
TrendMicro-HouseCallBKDR_PCLIENT.SMP
ClamAVWin.Worm.PcClient-5224
KasperskyBackdoor.Win32.PcClient.elty
BitDefenderGen:Variant.Bulz.824344
NANO-AntivirusTrojan.Win32.Generic.dhfky
AvastWin32:Trojan-gen
TencentTrojan.Win32.PcClient.mgen
EmsisoftGen:Variant.Bulz.824344 (B)
F-SecureTrojan.TR/Hush.A
DrWebBackDoor.PcClient.4794
ZillyaBackdoor.PcClient.Win32.16953
TrendMicroBKDR_PCLIENT.SMP
SophosMal/Agent-XN
IkarusBackdoor.Win32.PcClient
JiangminBackdoor/PcClient.aevs
GoogleDetected
AviraTR/Hush.A
VaristW32/PcClient.AE.gen!Eldorado
Antiy-AVLTrojan[Backdoor]/Win32.PcClient
KingsoftWin32.Hack.PcClient.elty
MicrosoftBackdoor:Win32/PcClient.CM
XcitiumTrojWare.Win32.PcClient.NOP@3976r8
ArcabitTrojan.Bulz.DC9418
ViRobotBackdoor.Win32.A.PcClient.104503.A
ZoneAlarmBackdoor.Win32.PcClient.elty
GDataGen:Variant.Bulz.824344
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Warezov.R1541
BitDefenderThetaGen:NN.ZedlaF.36802.gu5@aOXjLidj
ALYacGen:Variant.Bulz.824344
MAXmalware (ai score=100)
VBA32TScope.Malware-Cryptor.SB
Cylanceunsafe
PandaGeneric Malware
RisingBackdoor.PcClient!1.6490 (CLASSIC)
YandexTrojan.GenAsa!f1nb6kbisNU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1690221.susgen
FortinetW32/PcClient.GG!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/PcClient.NGO

How to remove Backdoor:Win32/PcClient.CM?

Backdoor:Win32/PcClient.CM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment